Skip to content

Instantly share code, notes, and snippets.

@j-keck
Created December 12, 2014 15:11
Show Gist options
  • Save j-keck/8a38273de23818d575e6 to your computer and use it in GitHub Desktop.
Save j-keck/8a38273de23818d575e6 to your computer and use it in GitHub Desktop.
cmdline
# tcpdump
* HTTP GET request
tcpdump -s 0 -A 'tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420'
* HTTP POST
tcpdump -s 0 -A 'tcp dst port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504f5354)'
* HTTP traffic
tcpdump -A -s 0 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)'
tcpdump -X -s 0 'tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment